Feature Compliance Strategy
FFIEC CAT Sunset: What Banks and Credit Unions Should Use Instead in 2026 — and What Examiners Now Expect
The FFIEC Cybersecurity Assessment Tool retired August 31, 2025, with no mandated replacement. NIST CSF 2.0 has become the de facto industry choice, but the transition isn't just swapping one framework for another. Here's what changed, what examiners look for now, and the documentation gaps most institutions missed.
Table of Contents
The FFIEC Cybersecurity Assessment Tool spent ten years as the default compliance framework for financial institution cybersecurity programs. Then, on August 31, 2025, it was retired — with no mandated replacement, no examination procedure update, and no official rubric telling institutions what to use instead.
The FFIEC’s formal reasoning was straightforward: NIST released CSF 2.0 in February 2024. Maintaining a parallel FFIEC-specific framework no longer made sense when a more current, widely adopted government standard was available. The retirement statement said, plainly, that the FFIEC had “determined not to update the CAT to reflect new government resources” — an acknowledgment that keeping the tool current would have required essentially rewriting it.
What the statement also said, and what many institutions overlooked: “Expectations for cybersecurity self-assessments have not changed; the only change is the retirement of the CAT.”
That’s the sentence that matters for examinations in 2026.
TL;DR
- The FFIEC CAT officially retired August 31, 2025 — no single replacement framework was mandated; examiner expectations did not change
- FFIEC pointed to four alternatives: NIST CSF 2.0, CISA CPGs, the CRI Profile, and CIS Controls — explicitly declining to endorse any one tool
- NIST CSF 2.0 has become the de facto industry choice, selected by approximately 73% of institutions in a June 2025 poll of 420+ financial institutions
- The biggest transition gap most institutions missed: the Govern function. NIST CSF 2.0’s new sixth function requires standalone governance documentation — board-approved risk appetite, explicit accountability structures, supply chain risk management — that the CAT embedded implicitly and that most institutions don’t have in written form
- Credit unions: the NCUA ACET continues independently and was updated in September 2025 — the FFIEC CAT retirement does not affect NCUA examination expectations
What the FFIEC Actually Said — and Why the “Outdated” Narrative Misses the Point
The CAT wasn’t retired because it gave bad guidance. The FFIEC was clear on this: “the fundamental security controls addressed throughout the maturity levels of the CAT are sound.” The retirement was about a maintenance decision, not a repudiation.
The FFIEC had updated the CAT once before, in May 2017. Keeping the tool current would have required a second major revision to reflect NIST CSF 2.0, updated supply chain risk management expectations, cloud security considerations, AI-related risks, and a dozen other developments since 2017. Rather than make that investment, the FFIEC concluded that NIST CSF 2.0 — already available and maintained by NIST — made more sense as the foundation going forward.
The FFIEC Press Release AN-09-29 was issued on August 29, 2024, with a one-year runway to the August 31, 2025 retirement date. All three primary FFIEC member agencies issued simultaneous guidance: Federal Reserve SR 24-7, OCC Bulletin 2024-25, and FDIC FIL-61-2024. All pointed to the same four alternatives. None mandated a specific choice.
The industry narrative around the CAT being “outdated” or “no longer meeting regulatory expectations” is analyst commentary, not regulatory language. That distinction matters when an examiner asks you to defend your framework choice — the correct answer is not “I switched because the CAT was outdated” but “I transitioned to [NIST CSF 2.0 / CRI Profile] because it better reflects current threat environments and aligns with our risk profile.”
The Four Alternatives and When to Use Each
NIST CSF 2.0
Released February 26, 2024, NIST CSF 2.0 is the first major update to the framework in a decade. The structural changes from version 1.1:
- Added Govern as a sixth core function (alongside Identify, Protect, Detect, Respond, Recover)
- Expanded supply chain risk management, now grouped under Govern rather than treated as a separate appendix
- Expanded scope from critical infrastructure to all organizations of all sizes
- Refined categories to 22 (from 23) and subcategories to 106 (from 108)
- Added practical implementation examples for specific outcomes
The addition of Govern is the most significant change. It has six explicit categories: Organizational Context (GV.OC), Risk Management Strategy (GV.RM), Roles and Responsibilities (GV.RR), Policy (GV.PO), Oversight (GV.OV), and Cybersecurity Supply Chain Risk Management (GV.SC). Approximately 30 percent of the framework’s subcategories fall under Govern — meaning governance documentation is no longer an afterthought in a compliant cybersecurity program.
NIST CSF 2.0 is the right choice for most financial institutions. The Federal Reserve’s May 2025 “Cybersecurity Resources for Community Banks” document names it as the primary resource for post-CAT compliance, explaining how to use it in examiner discussions.
Critical limitation: NIST CSF 2.0 does not include an inherent risk profile mechanism. The CAT’s Part 1 automatically calibrated assessment scope and expectations based on the institution’s size, technology complexity, delivery channels, and product mix. NIST CSF 2.0 Implementation Tiers (Partial, Risk-Informed, Repeatable, Adaptive) describe program maturity — not inherent risk level. Institutions transitioning from the CAT must build their own risk calibration methodology separately.
CRI Cyber Profile
The CRI Profile, maintained by the Cyber Risk Institute — a coalition of financial institutions and trade associations — is the most direct CAT replacement for institutions subject to multiple regulatory frameworks. At version 2.2 (April 30, 2026), the profile includes 318 diagnostic statements that synthesize requirements from NIST 800-53 rev.5, NIST CSF 2.0, FFIEC handbooks (including the recently updated DA&M Booklet), NYDFS Cybersecurity Regulation, CIS Controls, CISA CPGs, and dozens of other financial-sector regulatory sources.
The CRI Profile’s Impact Tiering mechanism partially replaces the CAT’s inherent risk profile: a 9-question questionnaire places institutions into one of four tiers, which determines how many of the 318 diagnostic statements the institution is expected to complete (Tier 1 institutions complete all 318; lower tiers complete reduced sets). Critics note the 9-question tiering is less granular than the CAT’s detailed inherent risk assessment — community banks that depended on the CAT’s automated risk calibration may find the CRI’s simpler tiering less useful for proportionality.
The CRI Profile’s key advantage is pre-built regulatory mapping. For institutions subject to NYDFS Part 500, OCC Heightened Standards, or FFIEC examination requirements simultaneously, the CRI translates all of those into a single assessment framework without requiring the institution to build cross-mapping documentation from scratch.
CISA CPGs and CIS Controls
CISA’s Cybersecurity Performance Goals and CIS Controls v8 are better understood as floors than as full replacements. CISA CPGs establish minimum cross-sector cybersecurity hygiene practices, aligned to NIST CSF. CIS Controls provide 18 control groups with Implementation Group tiers (IG1 for essential hygiene, IG3 for sophisticated programs).
Neither framework includes maturity measurement, inherent risk calibration, or financial-sector-specific regulatory mapping. For a community bank that used the CAT primarily to satisfy examiners with a structured assessment, CISA CPGs or CIS Controls IG1 work as a defensible baseline — if the institution also documents why that baseline is appropriate for its risk profile.
What Examiners Are Actually Looking for in 2026
The FFIEC’s retirement statement said examiner expectations had not changed. That’s technically correct and practically incomplete.
What changed is the framework that examiners reference. What didn’t change is the underlying question: does this institution understand its cybersecurity risks, manage them proportionately, and demonstrate active board-level oversight?
Post-CAT examination focus in 2026 concentrates on four areas:
Governance integration with enterprise risk management. The OCC Bulletin 2024-25 stated examiners “may address areas not covered by all tools at a point in time” — which is regulatory language for “having the tool doesn’t substitute for having a program.” What examiners look for is evidence that cybersecurity risk reaches the board, is reported through normal risk management channels, has a written risk appetite, and drives budget decisions. A NIST CSF 2.0 self-assessment filed in SharePoint does not demonstrate this. Board meeting minutes, a formal cybersecurity risk appetite statement, and management reports connecting assessment gaps to resource allocation do.
Incident response and operational resilience. Post-CrowdStrike examinations have shifted attention to whether institutions can actually recover, not just whether they have a plan. For software supply chain failure scenarios specifically, examiners now expect institutions to demonstrate tested recovery capabilities — not documented assumptions. This is covered under the NIST CSF 2.0 Respond and Recover functions, but the examination question is about actual testing, not framework completion.
Third-party and supply chain risk documentation. NIST CSF 2.0’s GV.SC (Cybersecurity Supply Chain Risk Management) requires documented processes for identifying, assessing, and managing cybersecurity risks in the supply chain. For institutions with cloud provider concentration risk, this category connects cybersecurity assessment to third-party risk management in ways the CAT’s External Dependency Management domain did not explicitly structure.
Documentation demonstrating active management. Regardless of which framework an institution uses, examiners want evidence that the assessment drives action — not that it was completed. The cycle should show: assessment completed, gaps identified, gaps reported to management and board, remediation initiated, prior gaps tracked to closure. The multi-regulator cyber incident notification requirements also connect here — institutions need cyber governance documentation that supports rapid notification decisions, not just cybersecurity assessment scores.
The Documentation Gaps Most Institutions Are Missing
Switching from the CAT to NIST CSF 2.0 isn’t only about completing a different assessment form. The CAT embedded certain governance evidence implicitly within its domain structure. NIST CSF 2.0 requires standalone documentation for content that previously lived inside the assessment tool itself.
The Govern function has no CAT equivalent. The CAT’s Domain 1 (Cyber Risk Management and Oversight) covered governance as one of five maturity domains. NIST CSF 2.0’s Govern function is a separate, first-class function with six categories. Meeting GV.RM requires a written cybersecurity risk management strategy. Meeting GV.RR requires explicit documentation of roles and accountability. Meeting GV.SC requires documented supply chain risk management processes. These are standalone documents — not assessment answers.
No inherent risk profile. The CAT’s Part 1 automatically generated an inherent risk level from detailed institutional data. Institutions that completed Part 1 received a calibrated risk level that justified their maturity target. NIST CSF 2.0 doesn’t include this. Institutions must separately document how they determined their appropriate implementation tier — which controls are relevant given their size, complexity, and risk profile. Examiners will ask how the institution’s framework implementation is calibrated to its risk level.
Framework mapping for prior assessment history. Institutions with years of CAT data need to explain how prior assessment work connects to the current framework. This isn’t just administrative housekeeping — examiners track whether prior gaps are closed. If a gap appeared in the 2023 CAT assessment and the institution has now switched to NIST CSF 2.0, the examiner will want to know whether that gap was addressed during the transition or carried forward.
Board-approved cybersecurity risk appetite. GV.OV requires oversight evidence that includes board engagement with cybersecurity risk. Many institutions have general risk appetite frameworks but not a specific, written cybersecurity risk appetite with defined thresholds. Creating this document — and getting board approval — is a new task for most institutions that relied on the CAT’s domain structure to demonstrate governance maturity.
Credit Unions: A Different Path
The FFIEC CAT retirement affects federally insured banks and thrifts. Credit unions have a separate situation.
The NCUA’s Automated Cybersecurity Examination Toolbox (ACET) continues as an independent tool. On September 16, 2025, the NCUA released an updated ACET application that: retained all original FFIEC CAT content for continuity; mapped the tool to NIST CSF 2.0 (updated from the prior 1.1 mapping); and included technical updates. The ACET remains completely voluntary — it introduces no new examination requirements.
Credit unions using the ACET are not affected by the FFIEC CAT retirement. Credit unions that weren’t using the ACET and were using the CAT directly should transition to the ACET, NIST CSF 2.0, or the CRI Profile — same decision framework as banks.
Practical Transition Steps for Institutions Still in Progress
For institutions that haven’t fully completed the CAT-to-replacement transition:
Document your framework selection rationale. The FFIEC said examiners take a risk-focused approach — which means the framework choice should reflect the institution’s specific risk profile, not just industry convention. One page explaining why NIST CSF 2.0 (or CRI Profile) is appropriate for the institution’s size, complexity, and regulatory environment is worth having before an examiner asks.
Complete a gap assessment against the new framework. Don’t carry CAT scores forward — map prior CAT controls to the new framework, identify what’s covered, and identify what the new framework adds that the CAT didn’t address. The Govern function categories and GV.SC supply chain management are the most common gaps.
Create standalone Govern function documentation. Draft a cybersecurity risk management strategy, an accountability matrix for cybersecurity roles, and a board-level risk appetite statement for cybersecurity. These don’t need to be long documents — they need to exist as documents that an examiner can review independently of the assessment tool.
Update board and management reporting templates. The CAT produced a risk profile output with percentage-based maturity scores that boards had learned to read. NIST CSF 2.0 reports differently. Management reporting needs a format that presents the institution’s cybersecurity posture clearly against the new framework, with gaps and remediation status that connect to examination expectations.
So What?
The FFIEC CAT is gone. The good news: the controls it assessed were sound, and if your cybersecurity program was mature under the CAT, it’s well-positioned under NIST CSF 2.0. The controls haven’t changed. The governance expectations have gotten more explicit.
The institutions most at risk in post-CAT examinations aren’t the ones that picked the wrong replacement framework. They’re the ones that picked a replacement framework, completed the assessment, and stopped there — without building the standalone governance documentation that the new framework requires, without connecting the assessment to board-level reporting, and without demonstrating that the transition actually closed prior gaps rather than just restarted the baseline.
NIST CSF 2.0 is the right choice for most institutions. The CRI Profile is worth serious consideration if regulatory mapping across multiple frameworks is a priority. What doesn’t work: completing a framework assessment once a year as a compliance exercise while governance documentation sits unwritten and board engagement remains nominal.
For compliance teams building out post-CAT cybersecurity governance documentation — risk appetite statements, framework mapping documents, board reporting templates, and governance structure artifacts that satisfy the NIST CSF 2.0 Govern function — the GRC Starter Kit includes the governance and risk management documentation foundation that supports a defensible cybersecurity program under current examiner expectations.
Sources:
- FFIEC Press Release AN-09-29: Retirement of Cybersecurity Assessment Tool
- FDIC FIL-61-2024: Sunset of FFIEC Cybersecurity Assessment Tool
- OCC Bulletin 2024-25: Retirement of FFIEC Cybersecurity Assessment Tool
- NIST CSF 2.0 — National Institute of Standards and Technology
- CRI Profile v2.2 — Cyber Risk Institute
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
GRC Starter Kit
Everything a new compliance hire needs to build their first risk program — 6 products at 46% off.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
When exactly did the FFIEC retire the Cybersecurity Assessment Tool?
Did the FFIEC mandate a specific replacement for the CAT?
What are banks and credit unions actually using to replace the CAT?
What is the NIST CSF 2.0 Govern function and why does it matter for banks?
What is the CRI Profile and how is it different from NIST CSF 2.0?
What are the biggest documentation gaps institutions have when transitioning off the FFIEC CAT?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
GRC Starter Kit
Everything a new compliance hire needs to build their first risk program — 6 products at 46% off.
◆ Keep reading
Related posts.
Compliance Strategy
GRC Framework for a Small Risk Team: One Control Library, Five Workflows, No Enterprise Platform
A GRC program that runs on one control library, five traceable workflows, and a set of spreadsheets beats a half-implemented enterprise platform every time. Here's how to build it.
Jul 24, 2026
Compliance Strategy
Compliance Monitoring Plan in Excel: Convert the Risk Assessment Into a Defensible Test Universe
Build a compliance monitoring plan template in Excel that traces risks and obligations to scope, evidence, exceptions, and remediation.
Jul 23, 2026
Compliance Strategy
Your Reg E Program Wasn't Built for FedNow: The Error Resolution Timeline Trap in Instant Payments
Reg E's 10-business-day provisional credit requirement applies to FedNow and RTP consumer transactions—but instant payment irrevocability means the fraud money is gone before you finish the investigation. Here's what your error resolution procedures actually need to say for instant payments, and where most programs have a documented gap.
Jul 22, 2026